Voilà!!
ComboFix 09-09-25.01 - Phil 2009-09-25 17:36.1.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1014.579 [GMT -4:00]
Lancé depuis: c:\documents and settings\Phil\Bureau\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Un antivirus résident est actif
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-1454471165-1677128483-515967899-1003
c:\recycler\S-1-5-21-152487977-4266136147-1633986092-1003
c:\recycler\S-1-5-21-1622952561-2354451018-2005075528-1003
c:\windows\010112010146101105.rx
c:\windows\Installer\34d2a5.msp
c:\windows\Installer\34d2a6.msp
c:\windows\Installer\34d2a7.msp
c:\windows\Installer\34d2a8.msp
c:\windows\Installer\34d2a9.msp
c:\windows\Installer\34d2aa.msp
c:\windows\Installer\34d2ab.msp
c:\windows\Installer\34d2ac.msp
c:\windows\Installer\34d2ad.msp
c:\windows\Installer\34d2ae.msp
c:\windows\msetup
c:\windows\msetup\MSetup.exe
c:\windows\rdr_1253746054.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SfX
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-25 au 2009-09-25 ))))))))))))))))))))))))))))))))))))
.
2009-09-25 15:29 . 2009-09-25 15:29 -------- d-----w- C:\_OTM
2009-09-24 22:40 . 2009-09-24 22:40 39424 ----a-w- c:\windows\zipinst.exe
2009-09-24 22:40 . 2009-09-24 22:40 -------- d-----w- c:\program files\regscanner
2009-09-24 21:46 . 2009-09-24 21:46 -------- d-----w- c:\documents and settings\Phil\Application Data\Malwarebytes
2009-09-24 21:46 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-24 21:46 . 2009-09-24 21:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-24 21:45 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-24 21:45 . 2009-09-24 21:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-24 18:41 . 2009-09-24 21:58 7470 ----a-w- c:\windows\fs1234.dat
2009-09-23 23:47 . 2009-09-23 23:50 -------- d-----w- c:\documents and settings\Phil\Application Data\Windows Live Writer
2009-09-23 23:47 . 2009-09-23 23:47 -------- d-----w- c:\documents and settings\Phil\Local Settings\Application Data\Windows Live Writer
2009-09-23 22:47 . 2009-09-23 22:47 51200 ----a-w- c:\windows\system32\fio32.dll
2009-09-23 22:47 . 2009-09-23 22:47 37632 ----a-w- c:\windows\system32\drivers\fio32.sys
2009-09-23 22:47 . 2009-09-23 22:47 1 ---h--w- c:\windows\bk23567.dat
2009-09-23 20:31 . 2009-09-23 20:31 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2009-09-23 20:31 . 2009-09-23 20:31 -------- d-----w- c:\program files\McAfee Security Scan
2009-09-23 20:27 . 2009-09-23 20:27 0 ----a-w- c:\windows\nsreg.dat
2009-09-23 20:26 . 2009-09-23 20:26 -------- d-----w- c:\documents and settings\Phil\Local Settings\Application Data\Mozilla
2009-09-23 03:08 . 2009-09-23 03:08 -------- d-----w- c:\windows\system32\XPSViewer
2009-09-23 03:08 . 2009-09-23 03:08 -------- d-----w- c:\program files\Reference Assemblies
2009-09-22 18:58 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-09-22 18:58 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-09-22 18:58 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-09-22 18:58 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-09-22 18:58 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-09-22 18:58 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-09-22 18:58 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-09-22 15:11 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-09-22 15:11 . 2008-06-14 17:33 272768 ------w- c:\windows\system32\drivers\bthport.sys
2009-09-22 14:11 . 2009-02-09 11:24 2191104 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-09-22 14:11 . 2009-02-09 11:23 2147328 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-09-22 14:11 . 2009-02-09 11:23 2025984 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-09-22 14:07 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-09-22 13:55 . 2007-11-30 11:18 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-09-22 02:11 . 2008-10-16 18:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-09-22 02:11 . 2008-10-16 18:06 208744 ----a-w- c:\windows\system32\muweb.dll
2009-09-20 23:37 . 2001-08-23 21:04 12288 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-09-20 23:37 . 2001-08-23 21:04 12288 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-09-20 23:37 . 2008-04-13 15:45 10368 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-09-20 23:37 . 2008-04-13 15:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-09-20 23:24 . 2009-09-20 23:24 -------- d-----w- c:\documents and settings\Phil\Bluetooth Software
2009-09-20 23:23 . 2008-07-24 08:37 156816 ----a-w- c:\windows\system32\drivers\btwdndis.sys
2009-09-20 23:23 . 2008-02-04 08:57 37160 ----a-w- c:\windows\system32\drivers\btport.sys
2009-09-20 23:23 . 2009-03-19 12:19 991136 ----a-w- c:\windows\system32\drivers\btkrnl.sys
2009-09-20 23:23 . 2009-02-18 08:46 534312 ----a-w- c:\windows\system32\drivers\btaudio.sys
2009-09-20 23:23 . 2009-09-20 23:23 -------- d-----w- c:\program files\WIDCOMM
2009-09-20 21:41 . 2009-09-20 21:41 -------- d-----w- c:\program files\uTorrent
2009-09-20 21:41 . 2009-09-25 02:49 -------- d-----w- c:\documents and settings\Phil\Application Data\uTorrent
2009-09-20 21:13 . 2009-09-20 21:24 -------- d-----w- c:\documents and settings\Phil\Application Data\Apple Computer
2009-09-20 21:12 . 2009-05-18 18:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-20 21:12 . 2008-04-17 17:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-09-20 21:11 . 2009-09-20 21:11 -------- d-----w- c:\program files\iPod
2009-09-20 21:11 . 2009-09-20 21:12 -------- d-----w- c:\program files\iTunes
2009-09-20 21:11 . 2009-09-20 21:12 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-20 21:10 . 2009-09-20 21:10 -------- d-----w- c:\program files\Bonjour
2009-09-20 21:08 . 2009-09-20 21:10 -------- d-----w- c:\program files\QuickTime
2009-09-20 21:08 . 2009-09-20 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-20 21:08 . 2009-09-20 21:08 -------- d-----w- c:\documents and settings\Phil\Local Settings\Application Data\Apple
2009-09-20 21:08 . 2009-09-20 21:08 -------- d-----w- c:\program files\Apple Software Update
2009-09-20 21:07 . 2009-09-20 21:07 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-09-20 21:07 . 2009-09-20 21:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-09-20 21:06 . 2009-09-20 21:57 -------- d-----w- c:\documents and settings\Phil\Local Settings\Application Data\Apple Computer
2009-09-20 20:30 . 2009-09-25 21:00 -------- d-----w- c:\documents and settings\Phil\Tracing
2009-09-20 20:26 . 2009-09-23 00:23 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-20 20:26 . 2009-09-20 20:26 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-09-20 20:20 . 2006-11-29 17:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-09-20 20:20 . 2009-09-20 20:20 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-09-20 20:19 . 2009-09-20 20:26 -------- d-----w- c:\program files\Microsoft
2009-09-20 20:18 . 2009-09-20 20:18 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-20 20:18 . 2009-09-20 20:26 -------- d-----w- c:\program files\Windows Live
2009-09-20 20:11 . 2009-09-20 20:11 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-09-20 20:11 . 2009-09-23 15:52 68464 ----a-w- c:\documents and settings\Phil\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-20 20:10 . 2009-09-20 20:10 -------- d-----w- c:\documents and settings\Phil\Contacts
2009-09-20 20:06 . 2009-09-20 20:06 -------- d-----w- c:\documents and settings\Phil\Application Data\MSNInstaller
2009-09-20 18:29 . 2006-10-26 23:56 32592 ----a-w- c:\windows\system32\msonpmon.dll
2009-09-20 18:27 . 2009-09-20 18:27 -------- d-----w- c:\program files\Microsoft Works
2009-09-20 18:27 . 2009-09-23 03:08 -------- d-----w- c:\program files\MSBuild
2009-09-20 18:22 . 2009-09-20 18:26 -------- d-----w- c:\windows\SHELLNEW
2009-09-20 18:21 . 2009-09-20 18:21 -------- d-----w- c:\documents and settings\Phil\Local Settings\Application Data\Microsoft Help
2009-09-20 18:21 . 2009-09-22 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-20 18:20 . 2009-09-20 18:20 -------- d-----r- C:\MSOCache
2009-09-20 18:19 . 2009-09-20 18:20 -------- d-----w- c:\documents and settings\Phil\Application Data\U3
2009-09-20 17:48 . 2009-09-20 17:48 -------- d-s---w- c:\documents and settings\Phil\UserData
2009-09-20 17:48 . 2009-09-20 20:01 -------- d-----w- c:\documents and settings\Phil\Local Settings\Application Data\Google
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-23 15:04 . 2009-06-18 14:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-09-23 03:12 . 2009-06-18 22:48 81790 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-23 03:12 . 2009-06-18 22:48 504042 ----a-w- c:\windows\system32\perfh00C.dat
2009-09-21 20:54 . 2009-06-18 14:18 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-09-21 20:31 . 2009-06-18 14:22 -------- d-----w- c:\program files\McAfee
2009-09-20 23:24 . 2009-06-18 14:16 -------- d-----w- c:\program files\Samsung
2009-09-20 23:22 . 2009-09-20 23:22 0 ----a-w- c:\windows\system32\drivers\144D_SAMSUNG_N_NC10_10CA.mrk
2009-08-05 09:00 . 2009-06-18 22:48 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:35 . 2009-06-18 22:48 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:35 . 2009-06-18 22:48 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 20:44 . 2009-07-26 20:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-17 19:03 . 2009-06-18 22:48 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-12 16:21 . 2009-06-18 22:48 233472 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 17:01 . 2009-07-10 17:01 307560 ----a-w- c:\windows\WLXPGSS.SCR
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-18 39408]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0\bin\jusched.exe" [2009-06-18 36972]
"EDS"="c:\program files\Samsung\Samsung EDS\EDSAgent.exe" [2007-12-20 659456]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-28 1044480]
"DMHotKey"="c:\program files\Samsung\Easy Display Manager\DMLoader.exe" [2006-12-27 466944]
"BatteryManager"="c:\program files\Samsung\Samsung Battery Manager\BatteryManager.exe" [2008-10-20 2768896]
"MagicKeyboard"="c:\program files\SAMSUNG\MagicKBD\PreMKBD.exe" [2006-05-14 151552]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-08-04 582992]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"SUPBackground"="c:\program files\Samsung\Samsung Update Plus\SUPBackground.exe" [2009-05-20 298664]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-08-26 16851456]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Phil\Menu D‚marrer\Programmes\D‚marrage\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-3-23 603488]
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:fio32
R?2 fioo32;fioo32;c:\windows\sYSteM32\SvchOst.eXE -k fioo32 [2009-06-18 14336]
R1 fio32;fio32;c:\windows\system32\drivers\fio32.sys [2009-09-23 37632]
R2 DOSMEMIO;MEMIO;c:\windows\system32\MEMIO.SYS [2009-06-18 4300]
R2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe -k yksvcs [2009-06-18 14336]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.SYS [2008-01-14 30208]
R3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\drivers\VMC326.sys [2009-06-18 238464]
S3 Partner Service;Partner Service;"c:\documents and settings\All Users\Application Data\Partner\partner.exe" --> c:\documents and settings\All Users\Application Data\Partner\partner.exe [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
yksvcs REG_MULTI_SZ yksvc
fioo32 REG_MULTI_SZ fioo32
.
Contenu du dossier 'Tâches planifiées'
2009-06-18 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-18 17:32]
2009-06-18 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-18 17:32]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.ca/mStart Page =
hxxp://www.google.com/ig/redirectdomain ... &bmod=SMSNuInternet Connection Wizard,ShellNext =
hxxp://www.google.com/ig/redirectdomain ... &bmod=SMSNuInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Envoyer à Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Phil\Application Data\Mozilla\Firefox\Profiles\ni2cwqyh.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.ca/FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPJPI150.dll
FF - plugin: c:\program files\Java\jre1.5.0\bin\NPOJI610.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-AdobeUpdater - c:\program files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-25 17:46
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(1524)
c:\windows\system32\btmmhook.dll
c:\windows\system32\eappprxy.dll
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\progra~1\mcafee\VIRUSS~1\scriptsn.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\FICHIE~1\McAfee\MNA\McNASvc.exe
c:\progra~1\FICHIE~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Samsung\MagicKBD\MagicKBD.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Heure de fin: 2009-09-25 17:50 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-09-25 21:50
Avant-CF: 64 311 173 120 octets libres
Après-CF: 64 396 042 240 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
302 --- E O F --- 2009-09-25 02:50